Vulnerability Database
Blog
FAQ
Docs
GHSA-mgmm-cmhj-2h5f
Suggest an improvement
Source
https://github.com/advisories/GHSA-mgmm-cmhj-2h5f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-mgmm-cmhj-2h5f/GHSA-mgmm-cmhj-2h5f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mgmm-cmhj-2h5f
Aliases
CVE-2023-0949
PYSEC-2023-33
Published
2023-02-22T09:30:18Z
Modified
2024-09-25T20:23:10.183094Z
Severity
4.8 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
4.6 (Medium)
CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Calculator
Summary
modoboa Cross-site Scripting vulnerability
Details
Cross-site Scripting (XSS) - Reflected in GitHub repository modoboa/modoboa prior to 2.0.45.
References
https://nvd.nist.gov/vuln/detail/CVE-2023-0949
https://github.com/modoboa/modoboa/commit/aa74e9a4a870162eea169e0a6a2eab841f8811b7
https://github.com/modoboa/modoboa
https://github.com/pypa/advisory-database/tree/main/vulns/modoboa/PYSEC-2023-33.yaml
https://huntr.dev/bounties/ef87be4e-493b-4ee9-9738-44c55b8acc19
Affected packages
PyPI
/
modoboa
Package
Name
modoboa
View open source insights on deps.dev
Purl
pkg:pypi/modoboa
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.0.5
Affected versions
0.*
0.7.0
1.*
1.2.0-rc2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.11.0
1.11.1
1.12.0
1.12.1
1.12.2
1.13.0
1.13.1
1.14.0
1.15.0
1.16.0
1.16.1
1.17.0
2.*
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
GHSA-mgmm-cmhj-2h5f - OSV